Worm Compromises Over 1,300 npm Packages Including Popular Caching Tools
A self-spreading worm called ChainDrop has compromised more than 1,300 npm packages, including popular ones like Keyv, Cacheable, and flat-cache.
The packages together have around 2 billion monthly downloads. The attack started after a maintainer’s GitHub account was compromised. The malware steals credentials and spreads by publishing new malicious versions.
Developers are urged to check their dependencies and rotate any exposed credentials.
Post #959
392
